Community discussions

MikroTik App
 
0ldman
Forum Guru
Forum Guru
Topic Author
Posts: 1465
Joined: Thu Jul 27, 2006 5:01 am

Routerboard pinging random addresses

Sun Mar 11, 2018 8:41 pm

I've got an RB600 that is pinging random IP addresses.

It has persisted through a wipe and reload. Unit has been in service since April of 2008. Getting ready to replace it, but something odd is going on. I'd like to get to the bottom of it.

Netinstall is not an option at the moment, maybe not at all. Ether1 is broken.

I'm less concerned about fixing this particular unit and more concerned with getting to the bottom of the problem.

I've cleared the unit, the *instant* a default route is added to the unit it starts pinging random addresses. Complete wipe, no default config, mac-telnet into the unit, add any address on that subnet, add a gateway, it starts pinging.
 
0ldman
Forum Guru
Forum Guru
Topic Author
Posts: 1465
Joined: Thu Jul 27, 2006 5:01 am

Re: Routerboard pinging random addresses

Sun Mar 11, 2018 9:26 pm

screenshot
You do not have the required permissions to view the files attached to this post.
 
User avatar
BartoszP
Forum Guru
Forum Guru
Posts: 3315
Joined: Mon Jun 16, 2014 1:13 pm
Location: Poland

Re: Routerboard pinging random addresses

Mon Mar 12, 2018 10:14 am

It is not router pinging but "outside world" is pinging your router and you IMHO have passing this traffic to 10.1.22.2 device with firewall's dst rule ... if 10.1.22.2 is LAN address not WAN.
 
arnoldmikro
newbie
Posts: 29
Joined: Sun Apr 14, 2013 5:12 pm
Location: miami fl usa

Re: Routerboard pinging random addresses

Mon Mar 12, 2018 3:32 pm

I dont agree with BartoszP , you have tx wit no rx do a sniffer capture on the packets. the bps is large whats inside?
 
User avatar
BartoszP
Forum Guru
Forum Guru
Posts: 3315
Joined: Mon Jun 16, 2014 1:13 pm
Location: Poland

Re: Routerboard pinging random addresses

Mon Mar 12, 2018 3:47 pm

It's your opinion but source address is public one and destination is local one. It seems to be obvious IMHO that traffic come from the world to LAN or to WAN interface if 10.x.x.x is address of WAN interface.

EDIT

Tx means that router transmits packets form "outside" to 10.x.x.x address. Router does not receives them as it is not destination of them ... we do not know DST-NAT rules.
 
Sob
Forum Guru
Forum Guru
Posts: 9188
Joined: Mon Apr 20, 2009 9:11 pm

Re: Routerboard pinging random addresses

Mon Mar 12, 2018 4:35 pm

I get confused by src/dst in Torch myself from time to time. But if you try it yourself, this really is how it looks like for outgoing traffic from router.
 
User avatar
CZFan
Forum Guru
Forum Guru
Posts: 2098
Joined: Sun Oct 09, 2016 8:25 pm
Location: South Africa, Krugersdorp (Home town of Brad Binder)
Contact:

Re: Routerboard pinging random addresses

Mon Mar 12, 2018 5:40 pm

It's your opinion but source address is public one and destination is local one. It seems to be obvious IMHO that traffic come from the world to LAN or to WAN interface if 10.x.x.x is address of WAN interface.

EDIT

Tx means that router transmits packets form "outside" to 10.x.x.x address. Router does not receives them as it is not destination of them ... we do not know DST-NAT rules.

My thinking tend to be inline with above.

From screenshot, ether2 IP seems to be 10.1.22.1, packets are coming in on ether2 from outside world destined for 10.1.22.2 and being forwarded to 10.1.22.2, the TX part.
Replies from 10.1.22.2 is not for ether2 / 10.1.22.1, but for outside world, i.e. passing through ether2, hence no RX on that interface.
Can also be being dropped by 10.1.22.2.
 
agnostic
Frequent Visitor
Frequent Visitor
Posts: 61
Joined: Fri Mar 21, 2014 8:23 pm

Re: Routerboard pinging random addresses

Mon Mar 12, 2018 8:06 pm

you didnt tell us if you have any pc connected to routerboard. from what i see it seems like an infected with virus pc pinging an ip with random src address. if it wasnt for tx traffic it would probably be from outside but now it is from inside your network. at first disconnect every machine from network and torch again. at second if you must have pc's connected you could try enabling tcp cookies and rp check filter so every packet with spoofed src address would be discarded.
 
Sob
Forum Guru
Forum Guru
Posts: 9188
Joined: Mon Apr 20, 2009 9:11 pm

Re: Routerboard pinging random addresses

Mon Mar 12, 2018 8:31 pm

As I understand it, the router is currently not routing, it's just connected to network, and there's barely any config except address (10.1.22.2) and gateway (10.1.22.1). And if that's the case, some process on router pinging random addresses would look exactly like this.